What Information Must Be Redacted? A PII Checklist
Redact anything that identifies a specific person on its own or can be combined with other details to identify them: Social Security and tax ID numbers, financial account numbers, dates of birth, home addresses, phone numbers, email addresses, health information, and government-issued ID numbers. The guiding principle across privacy rules is to share only what the task actually requires. This is general information, not legal advice, so confirm the exact obligations for your industry.
What counts as personal information?
Personal information is anything that points to one individual. Some of it identifies a person directly. The rest becomes identifying when you connect the dots. A single date of birth is not much on its own, but paired with a name and a ZIP code it can single someone out. That is why redaction decisions look at combinations, not just obvious identifiers.
The usual categories to check for in a document:
- Government identifiers: Social Security numbers, taxpayer IDs, passport and driver's license numbers.
- Financial data: bank and credit-card account numbers, routing numbers, and card security codes.
- Contact details: full home address, personal phone numbers, and personal email addresses.
- Dates and identity: date of birth, place of birth, and mother's maiden name.
- Health information: diagnoses, treatment records, insurance and medical record numbers.
- Sensitive attributes: biometric data, and login credentials or security answers.
What must be redacted in specific settings?
The baseline list changes depending on where the document is going.
In healthcare, the set of identifiers tied to a person's health is protected, and the standard is to strip identifiers that are not needed before a record is shared. Our guide to GDPR and HIPAA redaction covers how those rules shape the decision.
In court filings, the required identifiers are narrower and specific: Social Security and tax numbers, financial account numbers, birth dates, and minors' names, each cut to a partial form. Local rules can require more.
In business and HR records, contracts, offer letters, and internal reports often carry salaries, account numbers, and personal contact details that should come out before the document circulates beyond the people who need it.
When you release records to the public, such as under a public-records request, whole categories may be exempt from disclosure and have to be removed, including personal privacy details and law-enforcement information.
How do you decide what to remove?
Start from the purpose of sharing the document. Ask what the recipient actually needs to see. Everything that identifies a person and is not required for that purpose is a candidate for redaction. This "minimum necessary" habit is the same idea behind most privacy regulations, and it keeps you from over-sharing by default.
Two categories people miss:
- Indirect identifiers, like a rare job title in a small office, or a case number that maps back to a name.
- Hidden data, like document metadata, tracked changes, comments, and earlier text still stored in the file.
Why covering text does not count
Marking a field with a black box or a highlighter in a PDF hides the information from view while leaving it in the file. The text can be copied out, the box can be deleted, and the raw content can be extracted. For redaction to actually protect the data, the underlying content has to be removed: the characters, the pixels in an image, and any metadata carrying the same value. If you have ever wondered how leaks happen, our explainer on whether redaction can be reversed shows why cover-ups fail.
A checklist you can reuse
- Note the purpose of the document and who will see it.
- Scan for the direct identifiers above: government numbers, financial data, contact details, dates, and health information.
- Look for indirect identifiers that could single someone out in combination.
- Check hidden data: metadata, comments, tracked changes, and prior versions.
- Redact each item with a tool that deletes content rather than covering it. See how to redact a PDF for the mechanics.
- Verify by copying inside each redacted area and searching the file for values you removed.
- Keep the original safely and share only the redacted copy.
Keep the file private while you redact
There is a catch worth planning around. Uploading a sensitive document to an online tool just to redact it can disclose the very data you are trying to protect to a third party. Redacting in your browser avoids that, because the file never leaves your device.
Our free tool redacts entirely in the browser, removes content permanently, and never uploads your file. It handles PDFs and images, so a scanned form works the same way as a native PDF. Redact a document for free.
FAQ
What is the difference between direct and indirect identifiers?
A direct identifier names or numbers a person on its own, like a Social Security number. An indirect identifier only points to someone when combined with other details, like a birth date plus a ZIP code. Both can need redaction.
Do I need to redact metadata too?
Yes. Metadata, comments, tracked changes, and earlier saved text can hold the same personal data as the visible page. Good redaction removes hidden content, not just what is on screen.
Is redacting the same as deleting the file?
No. Redaction keeps the document usable while removing specific pieces of sensitive information from it. Done properly, the removed values cannot be copied, searched, or recovered from the shared copy.
How do I know my redaction worked?
Select and copy inside each redacted area, then search the file for a few characters you removed. If nothing comes back and the text cannot be selected, the content is gone rather than hidden.